Report forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Sun, 01 Aug 2021 22:33:01 GMT) (full text, mbox, link).
Acknowledgement sent
to Leo Famulari <leo@famulari.name>:
New bug report received and forwarded. Copy sent to guix-patches@gnu.org.
(Sun, 01 Aug 2021 22:33:02 GMT) (full text, mbox, link).
Hi Leo,
On 2021-08-01 23:31, Leo Famulari wrote:
> CVE-2021-3246 is "A heap buffer overflow vulnerability in msadpcm_decode_block
> of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted
> WAV file."
>
> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3246
What's blocking this from being merged?
(Perhaps it's also a chance to plug it into core-updates to avoid adding the variants?)
Cheers,
Bruno
Information forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Sun, 02 Apr 2023 20:17:01 GMT) (full text, mbox, link).
Sure, please feel free to add it to core-updates.
I never pushed it because 1) there was no feedback and 2) I no longer understand the patch.
On Sun, Apr 2, 2023, at 08:59, Bruno Victal wrote:
> Hi Leo,
>
> On 2021-08-01 23:31, Leo Famulari wrote:
>> CVE-2021-3246 is "A heap buffer overflow vulnerability in msadpcm_decode_block
>> of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted
>> WAV file."
>>
>> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3246
>
> What's blocking this from being merged?
> (Perhaps it's also a chance to plug it into core-updates to avoid
> adding the variants?)
>
>
> Cheers,
> Bruno
Information forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Mon, 03 Apr 2023 14:23:02 GMT) (full text, mbox, link).
On 2023-04-02 21:15, Leo Famulari wrote:
> Sure, please feel free to add it to core-updates.
>
> I never pushed it because 1) there was no feedback and 2) I no longer understand the patch.
I'm not a committer😅, could you CC it to the core-update maintainers?
Thanks!
Cheers,
Bruno
Added tag(s) security.
Request was from Bruno Victal <mirai@makinata.eu>
to control@debbugs.gnu.org.
(Tue, 04 Apr 2023 13:32:02 GMT) (full text, mbox, link).
Information forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Wed, 05 Apr 2023 08:47:02 GMT) (full text, mbox, link).
Cc: guix-devel@gnu.org, 49817@debbugs.gnu.org, Leo Famulari <leo@famulari.name>
Subject: Re: [core-updates] It would be nice to fix libsndfile CVE-2021-3246
(arbitrary code execution via crafted WAV file)
Date: Wed, 5 Apr 2023 10:46:05 +0200
Am Tue, Apr 04, 2023 at 08:13:19PM -0700 schrieb Felix Lechner via Development of GNU Guix and the GNU System distribution.:
> On Tue, Apr 4, 2023 at 7:49 PM Leo Famulari <leo@famulari.name> wrote:
> > See <https://issues.guix.gnu.org/issue/49817>, which was never applied
> > anywhere.
> > I guess it's enough to update libsndfile to 1.1.0 on core-updates.
> The upstream commit [2] shows that the issue was fixed in libsndfile's
> master branch as part of their merge request #713, which made it into
> these versions:
> 1.2.0
> 1.1.0
> 1.1.0beta2
> 1.1.0beta1
> It may therefore be better to upgrade directly to 1.2.0, except I
> think there was an understanding that no new features should be
> allowed on our core-updates branch at this time.
Well, an update causes a lot of rebuilds anyway. The NEWS of 1.2.0 look
like it is in fact only a bugfix release, so I took the risk to update to
this latest version. pulseaudio still compiles, and pavucontrol still works
on my machine.
The update is pushed to core-updates, but I would suggest to keep the bug
open until it is merged to master.
Thanks for the heads-up!
Andreas
Information forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Wed, 05 Apr 2023 15:55:02 GMT) (full text, mbox, link).
Cc: guix-devel@gnu.org, 49817@debbugs.gnu.org,
Felix Lechner <felix.lechner@lease-up.com>
Subject: Re: [core-updates] It would be nice to fix libsndfile CVE-2021-3246
(arbitrary code execution via crafted WAV file)
Date: Wed, 5 Apr 2023 11:54:13 -0400
On Wed, Apr 05, 2023 at 10:46:05AM +0200, Andreas Enge wrote:
> Well, an update causes a lot of rebuilds anyway. The NEWS of 1.2.0 look
> like it is in fact only a bugfix release, so I took the risk to update to
> this latest version. pulseaudio still compiles, and pavucontrol still works
> on my machine.
>
> The update is pushed to core-updates, but I would suggest to keep the bug
> open until it is merged to master.
Thank you Andreas!
Information forwarded
to guix-patches@gnu.org: bug#49817; Package guix-patches.
(Wed, 05 Apr 2023 16:21:01 GMT) (full text, mbox, link).
Cc: guix-devel@gnu.org, 49817@debbugs.gnu.org, Leo Famulari <leo@famulari.name>
Subject: Re: [core-updates] It would be nice to fix libsndfile CVE-2021-3246
(arbitrary code execution via crafted WAV file)
Date: Wed, 5 Apr 2023 09:19:43 -0700
Hi everyone,
On Wed, Apr 5, 2023 at 1:46 AM Andreas Enge <andreas@enge.fr> wrote:
>
> I would suggest to keep the bug
> open until it is merged to master.
Do we have a hook that closes such bugs automatically via instructions
in commit messages?
If not, I'd be happy to look into writing such a thing. It would also
help to tie commits to bug reports, which can be good for research
after the fact.
Kind regards,
Felix
Reply sent
to Andreas Enge <andreas@enge.fr>:
You have taken responsibility.
(Tue, 25 Apr 2023 13:51:02 GMT) (full text, mbox, link).
Notification sent
to Leo Famulari <leo@famulari.name>:
bug acknowledged by developer.
(Tue, 25 Apr 2023 13:51:02 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the
GNU Public License version 2. The current version can be
obtained from https://bugs.debian.org/debbugs-source/.